Real-Time Captcha Liveness Detection for Facial Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional facial and voice-based authentication systems are vulnerable to powerful and automated attacks, particularly deep learning-based techniques that can forge identities, making them ineffective against sophisticated impersonation methods.

Innovation Solution

The implementation of a Real-Time Captcha (rtCaptcha) system, which leverages CAPTCHA challenges to require users to solve video or audio recordings, imposing a significant computational burden on adversaries and ensuring human involvement, thereby preventing scalable attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional face- and voice-based authentication systems are used, then user authentication convenience is improved, but security against automated attacks deteriorates

Engineering Contradiction:
Improveauthentication convenienceVSAvoidsecurity against automated attacks
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces CAPTCHA as an intermediary challenge between the user and the authentication system. Instead of directly authenticating face or voice, the system first requires the user to solve a CAPTCHA, which acts as a mediator that automated attacks cannot bypass. This intermediary step maintains convenience for genuine users while blocking automated impersonation attempts.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system performs preliminary action by requiring users to solve CAPTCHA challenges before actual authentication occurs. This preliminary step verifies human presence and intent before the system processes sensitive biometric data, preventing automated attacks from reaching the authentication stage.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If simple liveness detection methods (smile/blink requests) are used, then ease of operation is improved, but security against impersonation deteriorates

Engineering Contradiction:
Improveliveness detection simplicityVSAvoidimpersonation resistance
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent inserts CAPTCHA solving as an intermediary task between simple liveness detection actions and authentication. While users perform simple actions like smiling or blinking, they must first solve a CAPTCHA, which prevents automated systems from executing these simple actions without human intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system merges multiple authentication factors: traditional liveness detection actions (smile/blink) are combined with CAPTCHA solving. This combination maintains the simplicity of physical actions while adding the security layer of cognitive verification, achieving both ease of operation and impersonation resistance.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If CAPTCHA challenges are introduced for liveness detection, then security against automated attacks is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity against automated attacksVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the universality of existing CAPTCHA technology, which can be integrated into various authentication systems without requiring custom development. By using established CAPTCHA frameworks, the system achieves enhanced security while minimizing the increase in complexity, as the CAPTCHA component can be implemented as a standardized module.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Reliability

If response time thresholds are enforced for CAPTCHA solving, then security against automated attacks is improved, but loss of time for legitimate users increases

Engineering Contradiction:
Improveautomated attack preventionVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies partial action by setting response time thresholds that are stringent enough to block automated attacks but reasonable enough to allow genuine users to complete CAPTCHA solving within acceptable time limits. The threshold is calibrated to be excessive for machines (which cannot solve CAPTCHA in time) but sufficient for humans, achieving security without excessive time loss.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS11663307B2RtCaptcha: a real-time captcha based liveness detection system
Publication Date: 2023.05.30 GEORGIA TECH RES CORP
  • US11663307B2 patent drawing
  • US11663307B2 patent drawing
  • US11663307B2 patent drawing

AI summary

Example systems and methods for defending against powerful, automated attacks on facial authentication systems are disclosed. A first verification is performed based at least in part on determining a response time for a response to a CAPTCHA or other challenge. In response to determining that the response time is within a threshold, a second verification is performed based at least in part on extracting a face feature or a voice feature from a plurality of samples associated with the response.